alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.
CVSS Details
- CVSS 4.0 Base Score: 4.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade alsa-ucmUpgrade alsa-libUpgrade alsa-lib-debuginfoUpgrade alsa-lib-develUpgrade alsa-lib-debugsourceUpgrade alsa-topology | Feb 20, 2026 | Jan 29, 2026 |
| Debian | — | Upgrade alsa-lib | Feb 9, 2026 | Feb 9, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 29, 2026 |
| Ubuntu | — | Upgrade libasound2Upgrade libasound2 (Ubuntu Pro)Upgrade libasound2t64 | Feb 17, 2026 | Jan 29, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub